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MEMORANDUM FOR: Director, National Foreign Assessment Center 
Deputy Director for Administration 
Deputy Director for Science and Technology 
Deputy Director for Operations 


FROM: James H. McDonald 

Director of. Logistics 
SUBJECT: Implementation of Task Force Recommendations 
REFERENCE: Industrial Contracts and Industrial Security 


Final Report dated February 1978 


1. The DCI's Task Force on Industrial Contracting and 
Industrial Security set forth a number of recommendations 
designed to strengthen the security aspects of Agency con- 
tracting procedures. Policy guidance on implementing the 
Task Force recommendations, given particular emphasis by the 
DCI, has been issued to procurement personnel in the attached 
OL Procurement Notes, also listed below: 


PN #103 - Industrial Contract Security - Determina- 
tion of Responsibility 
PN #115 - Security Performance Incentive in Incen- 


tive/Award Fee Contracts 
PN #116 - Enforcement of Security Provisions in 
Agency Contracts 
Security Requirements in Requests for 
Proposals. 


PN #117 


2. These Procurement Notes primarily address the Con- 
tracting Officer's responsibilities. Their effective imple- 
mentation, however, depends, on large part, on close cooperation 
between procurement, technical, and security personnel involved 
in contracting activities. Your assistance is, therefore, requested 
in disseminating the attached Procurement Notes to appropriate 
technical officers within your command structure and in en- 


couraging their support for early implementation of these 
policies. 


Bry 
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SUBJECT: Implementation of Task Force Recommendations 


3. Procurement Notes, in furtherance of several remaining 
Task Force recommendations, will be promulgated in the near 
future. Your assistance in this important matter will be 
greatly appreciated. 


STATINTL 


ames . cvona 


Att 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 103 


INDUSTRIAL CONTRACT SECURITY 
DETERMINATION OF RESPONSIBILITY 


i. In a recent letter prepared by the Director of 
Intelligence (DCI) for dissemination to Selected Agency con- 
tractors, concern was expressed regarding compliance with 
industrial contract security requirements. <A plea is mace in 
that same ictter for higher levels of consciousness and higher 
Standards of performance with regard “tO SCcurity aspects of 
Agency contracts. In this regard the DCI has stated: 


Central 


including the requirencnt that a contractor's 
security record and posture be taken into account 
when it comes to the award of new contracts and 
more effective provisions within our contracts with 
PCSpPece to security." 


"I have directed other initiatives as well, 


: Contracting officers are routinely required to make 
ain arlirmative determination of PEspousibilitv in aeccoriaacse 
with ASPR 1-902 which states that: “Purchasas shall be made 
from, and contracts shall be awarded to, responsible contrac- 
tors only.” To meet the minimum standards for an affirmative 
detcrmination of responsibility a contractor must: 


a, Have adequate financial resources, or the 
ability to obtain such resources as beguired durine 
performance of the contract (see Defense: Contract 
Pinancing Regulations, Part 2, Appendix E, and any 
amendments thereto; sce also 1-904.2 and 1-905.2; for 
SBA certificates of competency, sce AS 6S re ae 

b. Be able to comply with the require. or pre- 
posed delivery or performance scheduic, taking into 

consideration all existing busincss commitnents, 
“commercial as well as governmental (for SBA certifi- 
cates of competency, see i-75.4); 


OL 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 105 


c. Have a satisfactory recerd of performance 
(contractors who are seriously deficient in current 
contract performance, when the number of contracts 
and the extent of deficiency of each are considered, 
Shali, in the absence of evidence to the contrary or 
circumstances properly beyond the control of the 
contractor, be presumed to be unable to meet this 
requirement). Past unsatisfactory performance, due 
to failure to apply necessary tenacity or perseverance 
to do an acceptable job, shall be sufficient to JUStity 
a finding of nonresponsibility. (In the case of small 
business concerns, see 1-705.4(c) (vi) and 1-905.2); 


d, tTlave a satisfactory record of Lnoce rity 
(in the case of a small business concern, seo 1-705.4 


Cer. eads 


¢. Be otherwise qualified and eligible to receive 
an award under applicable laws and regulations, e.g., 
section XII, Parts 6 and 6 (in the case of a small 
bUSINESS Concern. X46 Ee FOS CC) Ry jes 


5. Compliance with applicable security reauirements, 
whether imposed by statute, regulation or cmbodicd in contract 
terms and conditions, is a critical element in performance of 
contracts for this Agency. As such, contracting officers are 
directed to review existing procedures which require coordina- 
tion with a cognizant representative of the Office of security 
prior to execution of any contract which involves classified 
information. They may not execute any contract involving 
Classified information (work, reports, association hardware, 
etc.) without certification from their cognizant security 
representative regarding the contractor's current SCCuraLy 
capability as well as the contractor's record of past performance 
in complying with security requirements. Approval by the coeni- 
zant security representative cf contractor Fesponrsi bility an 

the arca of compliance with industrial contract SOCcurity 
requirements must be evidenced by his Signature on Form L 
Procurement Justification and Routing Sheet, in c 
with existing procedures. 


mm 2218, 
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OPP ICE OF LOGISTICS 
PROCUREMENT NOTE NO. 193 


4. New, stronger security clauses for inclusion in 
Agency contracts are in process and will be promulgated 
upon completion. 


STATINTL 


Janes H. McDonald” 
fos IDES SCEOE Of Lorise tes 


CONCUR: 


Associate General Counsel Date 
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OPPIGE OF BOULSTICS 
PROCUREMENT NOTE NO. 115 


SECURITY PERFORMANCE INCENTIVE 
IN INCENTIVE/7AWARD FEE CONTRACTS 


1. The Task Force on Industrial Security and Industrial 
Contracting recommended in its interim report that incentive/ 
award fee type contracts include security performance, along 
With other performance requirements, as a basis for fee deter- 
mination. The DCI has approved this concept and has noted 

that the value of products and/or services required through 
industrial contracts may be diminished or negated if security 
is compromised. This procurement note is issued to provide 


policy guidance on implementation of the Task Force recom- 
mendation. 


2. U€fective this date, procurement personnel are di- 
rected fo incorporate security performance criteria in award 
fee and combination incentive/award fee contracts. This policy 
is not applicable to other incentive fee arrangements. The 
purpose of establishing security performance critcria as one 
determinant of award fee is to provide a meaningful incentive 
to contractors, balanced against the primary contract objec- 
tive of obtaining products and/or services. Security per- 
formance criteria Shalt “cheveto cence tailored ta the unique 
requirements of each contract action, and no standard pre- 
determined weight shall be assigned to this performance fac- 
tor. The weight given to security performance criteria should 
be based on the sensitivity of the contemplated effort, and 
determination of the relative importance of security versus 
other selected performance factors. Generally, there will be 
a direct correlation between the soe eee) of the contem- 


plated effort and the weight assigned to security performance 
Criteria. 


a 


i: Tt. 2S. CUpPhastized that. this requirenent’ ws: cloesély 
linked 0° tic prenceotiition activities of (a) siroposal 
solicitation in which contemplated security requirements are 
established and the contractor's plan for satisfying those 
requirements is requested, and (b) proposal eet during 
which the contractor's security plan will be assessed, and 

i COMpPOtLt ive: Sltvations: wited As <a part. of the Breen 
Source Selection. process. 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 115 


4. Security performance criteria shall be established in 
a manner similar to other selected performance criteria and 
will result in a unilateral determination by the Government not 
subject to the contract disputes clause. In selecting these 
criteria, consideration should be given to security require- 
ments established prior to proposal solicitation, the con- 
tractor's proposed security plan and the Government's evalua- 
tion thereof, and the security requirements to be incorporated 
in the anticipated contract Examples of subclements that 
might be used to define security performance include timely 
submission of contractor personne} security approval requests; 
proper handling and processing of classified contract data and 
documents; contractor's responsiveness to instructions and 
requirements of Agency security representatives; contractor 
compliance with security requirements unique to the contract; 
contractor performance regarding poate classification of 
contract documents and data; promptness and diligence in 
correcting deficiencies noted during contractor security 
inspections; contractor's success in avoiding compromise of 
classified information: contractor's record regarding reported 
security violations; and contractor's overall record of 
compliance with established Agency security procedures and 
directives. 


5. It is recognized that this policy injects a new 

evaluation element into the determination of award fees 
under Agency contracts and that careful planning will be 
required for its successful implementation, Accordingly, 
attention must be given to this requirement ecariy in the 
eerie cycle. Procurement personnel shall be respon- 

ible for implementing this policy and necessary coordination 
vith technical personnel involved in evaluating contractor 
performance and performing award fee evaluations. Compliance 
with the requirements of this Procurement Note will be 
reviewed during scheduled inspections of decentralized 
contract teams und as a part of reviews by the Agency 
Contract Review Board. 


f Director of Logistics 
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OFFICE OF LOGISTICS | : 
PROCUREMENT NOTE NO. 116 oe Ti JUL 1878 


ENFORCEMENT OF SECURITY PROVISIONS 
IN AGENCY CONTRACTS ' 


The Task Force on Industrial Contracts and Industrial 
Security recommended and the DDCI has directed: 


"That the Director of Security be responsible 
for monitoring the security responsibilities of the 
contractor. The enforcement of contract terms, 
including those covering security performance, remain 
the responsibility of the contracting officer." 


"That remedies available in contract law be 
used as the primary means of enforcing contractor 
compliance with industrial security standards." 


While these directions. do not change procedures which 
have been used on a continuing basis for several years, we 
believe it is necessary to emphasize the importance of the 
respective roles of the contracting officer and his security 
representative in the enforcement of security provisions of 
our Agency contracts. 


SNE Since the damaging matter, a multifaceted 
program has been under way in an attempt to shore up our 
industrial security program. For example, stronger security 
clauses are in process. Security manuals are being revised. 
Contracts are being incentivized to provide either reward 

or penalty for. contractor security performance. Contractors 
are being inspected by teams from the Agency and security 
performance has been identified as a critical item in award 
of contracts. 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 116 


Admiral Turner, in a September 1977 letter to our 
contractors, has said: 


"T want to make it clear that I regard security 
as being of central importance in the performance of 
contracts funded or administered by this Agency. 
Nearly all of the work under contract would be of 
lesser value, and much of it would be of little value 
if it could not be performed in a secure manner and 
protected against unauthorized disclosure, whether 
deliberate or inadvertent, which I have the statutory 
obligation to protect." 


Contractor compliance with industrial contract security 
requirements must be of greater concern to each of us involved 
in the procurement process than at any time in the past. Some 
contractors have very effective security programs and actively 
seek to improve them; most contractors need to effect higher 
standards, Overall security policy standards and the monitoring 
thereof are Office of Security responsibilities. Enforcement 


of security requirements are the responsibility of the contracting 
officer. 


Contracting officers are directed, in light of the DDCI 
direction, above, to again review and to maintain a working 
knowledge of the security requirements expressed in the General 
Provisions (Section A, Article 23), Procurement Note numbers 
58, 103 and 115 as well as the appropriate security clauses of 
the contract schedule, and existing security procedures. Com- 
pliance with applicable security requirements, whether imposed 
by statute, regulation, General Provisions or embodied in 
contract terms and conditions, shall be strictly enforced. 


STATINTL Contracting officers are again reminded that they may not 
execute any contract involving classified information (associa- 
tion, work, reports, hardware, etc.) without certification from 
their cognizant security representative regarding the contractor's 
current security capability as well as the contractor's record 
of past performance in complying with security requirements. 


= : oa 


Director of Logistics 
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OFFICE OF LOGISTICS ie ee 
PROCUREMENT NOTE NO. 117 cS See Se aary 


SECURITY REQUIREMENTS IN REQUESTS FOR PROPOSALS 


1. The Task Force on Industrial Contracts and Industrial 
Security recommended in its interim report that "requests for 
proposals which anticipate classified contracts describe 
security requirements and require that the contractor include 
in his proposal his plan for satisfying those requirements." 
The purpose of this Procurement Note is to implement the above 
recommendation. 


2. While it has been common practice to describe the 
security requirements of a contemplated contract in Agency 
RFP's, potential offerors have not generally been instructed 
to submit a formal plan for meeting these requirements. Effec- 
tive this date, procurement personnel are directed to include 
a requirement in RFP's for offerors to submit a plan for 
satisfying security requirements of the anticipated contract 
in their proposals. The size and complexity of the offeror's 
security plan will depend upon the magnitude of security 
requirements in the RFP. In some cases,. one paragraph in the 
offeror's proposal may suffice, while in others a multipart 
document may be necessary. In any event, the security plan 
should demonstrate that the offeror has a full comprehension 
of the security requirements and intends to comply with same. 


3. Logistics Instruction No. 45-30 dated 14 June LOTS; 
a copy of which is attached, establishes the requirement for 
completion of a Contract Data Classification Guide (CDCG) 
prior to execution of all contracts exceeding $10,000 in value 
where work, reports, association, hardware, or production 
equipment is determined to be classified. The CDCG will be 
incorporated in such contracts by reference. The Contracting 
Officer's Technical Representative is responsible for completion 
of the CDCG; however, his determinations of security classifi- 
cation will very likely involve coordination and discussions 
with the Contracting Officer and cognizant Industrial Security 
Officer. Procurement personnel should encourage COTR's to 
make CDCG security determinations prior to solicitation of 
proposals as this document, properly completed, can then be 
used as a basis for establishing security requirements in the 
RFP, 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 117 


4. <A representative listing of matters that should be 
addressed in offeror's proposed security plans is attached. 
Contract security requirements and criteria for evaluating 
proposed security plans should be tailored to the unique 
circumstances of each contract action. Therefore, the 
attached listing is intended to provide only general guidance 
regarding matters to be covered in offeror's proposed security 
plans. — 


9. Procurement personnel will be responsible for 
implementing this policy and effecting necessary coordination 
with technical and security personnel. Compliance with the 
requirements of this Procurement Note will be reviewed during 
Scheduled inspections of decentralized contract teams and 
included as a part of reviews by the Agency Contract Review 
Board, : 


STATINTL 


ames H. McDonald 
irector of Logistics 


Att 
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LOGISTICS INSTRUCTION NO. LI 45-5 
LI 45-530 LOGISTICS 
21 June 1373 


SUBJECT: Industrial Contract Se Soren s - 
Contract Data Classification Guide 


REFERENCES: a. mm Classified Contract Security 


be AOL CEOs Logistics Procurement Note No. 103 
Industrial Contract SeCUTILy 


STATINTL 


1. PURPOSE 


This instruction supplements existing vrocedures governing the 
Agency's classified procurenen activities which will identié 
with more specificity the security classification of the ela 
ments and vroducts thereof. 


Ld . SOUTCY 


a. Actherence to the security policy and standards for indusc-r 
contractual arrangements established by the Director of 
Security is a critical element in the administration of con- 
tracts for this Agency. 


eee | 
ace Lb 


b. The Contract Data Classificetion Guide (CBCG)* will be con- 
pleted on all procurement actions for materiei and/or services 
anticipated to exceed $10,000 and where tho work, Feports; 
association, hardware, or production equipment is determined 
to be classified. 


Cy. oA copy of the completed CDCG will accompany the contrac 
it is forwarded to the contractor for sianature ‘ ae 
serve to nctifty the contractor of the SOCCUST Ty Claes es 
of the key elements associated with cae. CONtE aes. - Pets 
become a permanent part of all official copies of the 
EVact, 


7] 


State that this is not an all-inclusive 
CDCG-may be a part of the contract, it 
ance for contractor handling of classifie 


d. The contract clause incorporating the CDCi 


* To be reproduced locally 
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Material produced under the contract and not specifically 
covered by the CDCG will still require the contractor to 
seek Agency guidance regarding its handling, 


de. RESPONSTBILITIES 

a. Effective immediately, Contracting Officers will not execute 
any contract of which any aspect is classified without a 
properly executed CDCG, 

b. The CDCG will be completed by the Contracting Officer's 
Technical Representative and provided the Contracting Officer 
as an attachment to the Request for Procurement Services 
(Form No. 2420) or the Requisition for Materiel and/or 
Services (Form No. 88) as appropriate. 

STATINTL 
a all » MODOWA LD 
Director of Logistics 
é 
Attachment 
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(ENTER APPROPRIATE CLASSIFICATION OF DATA OPPOSITE EACH ITEM BELOW) 


CLASSIFICATION 
CONTRACT NO. (CONF-SECRET~-TS~GTHER) 


GOVERNMENT FURNISHED DATA: 


Contract 


Statement of Work 


Technical Information 


Specifications 


Drawings 


Graphics 


Computer Software 


Communication Security (COMSEC) Material 


Other (attach sheet for additional Data items) 


II. CONTRACTOR PRODUCED DATA: 
A. Reports 
. Preliminary 
» Interim 
- Final 


- Manuals 


1 
2 
3 
4 
5. Drawings 
6. Graphics 
7. Computer Software 
8. Other (attach sheet for additional Data items) 
B. Hardware: (identify and note if sight sensitive) 
» Component 
» System 


- Sub-system 


- Prototypes 


1 
2 
3 
4. Breadboards 
5 
6. Engineering Models 
7 


» Other (attach sheet for additional Data items) 


III. CRITICAL SECURITY ELEMENTS OF PROCUREMENT: (Statement) 
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Items Typically Covered in Offeror's Security Plans 


Introduction/Objectives 


Security Organization 
a. Key Personnel 
b. Guard Force 
c. Fire/Safety Protection 


Personnel Security 
a. Personnel Screening 
b. Access Processing 
c. Security Questionnaire 
d. Security Training/Education 


Facility Security 
a. Plan Protection - 
b. Project/Program Work Area 
c. Personnel Identification 
d. Visitor Control 


Contracts and Finance 
a. General 
b. Job Authorizations 
c. Vouchers 
d. Audits 


Material Procurement 
a. Routine Unclassified Procurement 
b. Special Unclassified Procurement 
c. Classified Procurement 
d. Subcontract Security 


Automatic Data Processing 
a. General 
b. Storage, Protection and Control 
Keypunch Operations 
Library 
Vendor Service Technicians/Maintenance Log 
Audit Trail 
Subcontracting 
- Emergency Plan/System Crash/Compromise 


Approved For Release 2002/01/15 : CIA-RDP81-00142R000600090014-5 


Approved For Release 2002/01/15 : CIA-RDP81-00142R000600090014-5 


8. Communications Security 
a. Sterile Post Office Boxes 
b. Sterile Telephones 


9. Emergency Plans 
a. Fire Response 
b. Civil Disorders 
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